plugins/scmcvs/www/cvsweb.php in the CVSWeb CGI in GForge 4.5.16 before 20070524, aka gforge-plugin-scmcvs, allows remote attackers to execute arbitrary commands via shell metacharacters in the PATH_INFO.
| Name | Vendor | Start Version | End Version |
|---|---|---|---|
| Gforge | Gforge | * | 4.5.16 (including) |
| Gforge-plugin-scmcvs | Ubuntu | feisty | * |